Dear Ltangel,
First good news, The IE is performing much faster than before :)))
Since I couldn't find the "xing shared" file, I tried to perform a search and got a message "Can not perform search, a file that is required to run search companion cannot be found"
Here is my log:
ComboFix 08-03-20.5 - Betty 2008-03-22 14:40:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1688 [GMT 1:00]
Running from: C:\Documents and Settings\Betty\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Betty\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\!KillBox
C:\!KillBox\jncixdct.dll ( 1)
C:\!KillBox\Logs\kb.log
C:\!KillBox\mloiotut.dll
C:\!KillBox\qomlmjg.dll ( 2)
C:\!KillBox\qomlmjg.dll
C:\!KillBox\qomlmjg.dll( 2)
C:\!KillBox\skeysw.exe
C:\Documents and Settings\Betty\Application Data\Comma Separated Values (Windows).ADR\
C:\Documents and Settings\Betty\Application Data\DNA
C:\Documents and Settings\Betty\Application Data\DNA\dht.dat
C:\Documents and Settings\Betty\Application Data\DNA\dht.dat.old
C:\Documents and Settings\Betty\Application Data\DNA\resume.dat
C:\Documents and Settings\Betty\Application Data\DNA\resume.dat.old
C:\Documents and Settings\Betty\Application Data\DNA\settings.dat
C:\Documents and Settings\Betty\Application Data\DNA\settings.dat.old
C:\Documents and Settings\Betty\Application Data\LimeWire
C:\Documents and Settings\Betty\Application Data\LimeWire\.NetworkShare\LimeWireWin4.16.6.exe
C:\Documents and Settings\Betty\Application Data\LimeWire\410splashpro.png
C:\Documents and Settings\Betty\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Betty\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Betty\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Betty\Application Data\LimeWire\filters.props
C:\Documents and Settings\Betty\Application Data\LimeWire\gnutella.net
C:\Documents and Settings\Betty\Application Data\LimeWire\installation.props
C:\Documents and Settings\Betty\Application Data\LimeWire\library.dat
C:\Documents and Settings\Betty\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Betty\Application Data\LimeWire\pub1.key
C:\Documents and Settings\Betty\Application Data\LimeWire\public.key
C:\Documents and Settings\Betty\Application Data\LimeWire\questions.props
C:\Documents and Settings\Betty\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Betty\Application Data\LimeWire\spam.dat
C:\Documents and Settings\Betty\Application Data\LimeWire\tables.props
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme.lwtp
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\01_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\02_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\03_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\04_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\05_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\chat.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\dir_closed.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\dir_open.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\forward_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\forward_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\kill.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\kill_on.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\lime.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\logo.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\notsearching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\pause_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\pause_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\play_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\play_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\question.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\rewind_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\rewind_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\searching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\splash.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\stop_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\stop_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\theme.txt
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\black_theme\warning.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme.lwtp
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\01_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\02_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\03_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\04_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\05_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\chat.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\dir_closed.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\dir_open.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\forward_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\forward_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\kill.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\logo.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\notsearching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\pause_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\pause_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\play_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\play_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\question.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\rewind_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\rewind_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\search.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\searching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\splash.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\stop_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\stop_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\theme.txt
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\classic_theme\warning.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme.lwtp
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\01_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\02_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\03_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\04_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\05_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\chat.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\dir_closed.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\dir_open.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\forward_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\forward_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\kill.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\kill_on.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\lime.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\logo.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\notsearching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\pause_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\pause_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\play_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\play_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\question.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\rewind_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\rewind_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\searching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\splash.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\stop_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\stop_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\theme.txt
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewire_theme\warning.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme.lwtp
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\01_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\02_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\03_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\04_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\05_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\chat.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\dir_closed.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\dir_open.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\forward_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\forward_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\kill.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\kill_on.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\lime.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\logo.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\notsearching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\pause_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\pause_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\play_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\play_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\question.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\rewind_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\rewind_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\searching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\splash.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\stop_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\stop_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\theme.txt
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\limewirePro_theme\warning.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme.lwtp
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\01_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\02_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\03_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\04_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\05_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\chat.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\forward_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\forward_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\kill.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\kill_on.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\logo.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\notsearching.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\pause_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\pause_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\play_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\play_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\question.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\rewind_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\rewind_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\searching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\splash.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\stop_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\stop_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\theme.txt
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\other_theme\warning.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\01_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\02_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\03_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\04_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\05_star.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\notsearching.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\splash.png
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Betty\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\ttree.cache
C:\Documents and Settings\Betty\Application Data\LimeWire\update.xml
C:\Documents and Settings\Betty\Application Data\LimeWire\version.key
C:\Documents and Settings\Betty\Application Data\LimeWire\version.xml
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\data\application.sxml
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\data\audio.sxml
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\data\delete_me
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\data\video.sxml
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\misc\application.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\misc\audio.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\misc\document.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\misc\image.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\misc\video.gif
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\schemas\application.xsd
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\schemas\audio.xsd
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\schemas\document.xsd
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\schemas\image.xsd
C:\Documents and Settings\Betty\Application Data\LimeWire\xml\schemas\video.xsd
C:\Documents and Settings\Betty\Application Data\Personal Address Book.ADR\
C:\IRCap
C:\IRCap\Crack\779b31484656d7207ff1d8e2c7a5ac1f896.zip
C:\IRCap\Crack\keygen.exe
C:\IRCap\Crack\XBiNX.nfo
C:\IRCap\mirc62.exe
C:\Program Files\Common Files\xing shared
C:\Program Files\Common Files\xing shared\mpeg encode\xmencmp3.dll
C:\VundoFix Backups
C:\VundoFix Backups\aacgptld.dll.bad
C:\VundoFix Backups\dltpgcaa.ini.bad
C:\VundoFix Backups\mllml.dll.bad
C:\VundoFix Backups\pmnlj.dll.bad
C:\VundoFix Backups\ssttt.dll.bad
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\lnnmp.ini
C:\WINDOWS\system32\lnnmp.ini2
C:\WINDOWS\system32\pmnnl.dll
C:\WINDOWS\system32\stutv.ini2
C:\WINDOWS\system32\wdkcepyq.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-22 to 2008-03-22 )))))))))))))))))))))))))))))))
.
Download Sophos Anti-Rootkit & save it to your desktop after filling out the questionaire and reading the EULA.
Note: You will need to enter your name, e-mail address and location in order to access the download page. [*]Double-click sarsfx.exe to extract the files.
[*]Click the Accept button at the EULA, then Install to the default directory
[*]At the next prompt, click Yes to start the program
[*]Make sure the following are checked:[list]
[*]Running processes
[*]Windows Registry
[*]Local Hard Drives
[*]Click the "Start Scan" button.
[*]Allow the program to scan your computer - please be patient as it may take some time
[*]Once the scan has completed a window will pop-up with the results of the scan - click OK to this
[*]In the main window, you will see each of the entries found by the scan (if any)
[*]If the scanner generated any warning messages, please click on each warning and copy and paste the text of it into this thread for me to review
[*]Once you have posted any warning messages here, you can close the scanner and wait for me to get back to you
[*]If you have not had any warnings, any entries which can be cleaned up by the scanner will have a box with a green checkmark in it next to the entry
[*]To clean up these entries click on the Clean up checked items button
[*]If you accidentally check a file NOT recommended for clean up, you will get a warning message and if necessary can re-select the entries you want to clean up
[*]Once you have cleaned the selected files, you will be prompted to re-boot your computer - please do so
[*]When you have re-booted, please post a fresh HijackThis log into this thread and tell me how your computer is running now and if any rootkits have been found(please take down the file names of the rootkits found).
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
[*]Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
[*]If an update is found, it will download and install the latest version.
[*]Once the program has loaded, select "Perform Quick Scan", then click Scan.
[*]The scan may take some time to finish,so please be patient.
[*]When the scan is complete, click OK, then Show Results to view the results.
[*]Make sure that everything is checked, and click Remove Selected.
[*]When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
[*]The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
[*]Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
* Fresh HijackThis Log (after completing everything)
* ComboFix.txt
* Report on rootkit scan and computer performance(please tell me the names of all the rootkit files found, if any)
* MalwareByte's Anti-Malware log
2. Appeared after rebooting (after Combofix)
3. After running Sophos-Anti-Roothit, there were ?no hidden files found by scan?
Here is the first Hijack this:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:01:39 PM, on 3/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Sammsoft (Rogue.Advanced.Registry.Optimizer) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
And the seconf Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:13:16 PM, on 3/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
ComboFix 08-03-20.5 - Betty 2008-03-22 15:43:01.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1629 [GMT 1:00]
Running from: C:\Documents and Settings\Betty\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Betty\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
First of all I would like to wish you and your loved ones a very happy Easter.
I am sorry we didn't get to finish fixing my computer. I hope you will be available to help me again when I return on the 6th of April. I am also sorry I made you spend so much of your time with me, you are truly a wonderful person.
so sorry about your problems but i would suggest a complete reinstall of your operating system i only use AVG free version and would you believe i have no problems with any viruses . also i use win xp system restore my operating system is WIN XP PRO.. regards win restore i disable at least twice per week but imediately start it up again then do a clean restore point ; if you are not careful system restore restore will keep re- installing any viruses you may have on youe system peterpeck
Dear Peterpeck,
Thank you for your suggestions, I am sure they are good. However, I have been following Ltangel's instructions from the beginning and all the way he/she has been absolutely wonderful to me. I know I have to follow the instructions to the end; his/her help has been absolutely great!!
hell yeah they were great wow man, I wished i knew everything you did! are you self-taught? I mean, I know how to do this stuff onsite but, you take it to a whole new level!
Originally posted by thor999: hell yeah they were great wow man, I wished i knew everything you did! are you self-taught? I mean, I know how to do this stuff onsite but, you take it to a whole new level!
I have gone through proper training from malware removal experts, and have been doing this for quite a while. :) If you want to learn about malware removal, please PM me.
Thank you so much for all your help through my crisis, you were very supportive. I understand you were very busy but I needed my PC and couldn't wait any longer so I took it to a professional who did the fixing for me. (I hope he did!!)
Thanks again for being there for me.
I wish you all the best.
Tigrita